Dergiler / Turkish Journal of Electrical Engineering and Computer Sciences / 2019 / Cilt: 27 - Sayı: 1

Formally analyzed m-coupon protocol with confirmation code (MCWCC)

Sayfa
484–498
DOI
—

Abstract

There are many marketing methods used to attract customers’ attention and customers search for specialdiscounts and conduct research to get products cheaper. Using discount coupons is one of the widely used methodsfor obtaining discounts. With the development of technology, classical paper-based discount coupons become e-couponsand then turn into mobile coupons (m-coupons). It is inevitable that retailers will use m-coupon technology to attractcustomers while mobile devices are used in daily life. As a result, m-coupon technology is a promising technology. Oneof the significant problems with using m-coupons is security. Here it is necessary to ensure the safety of the seller’sand retailer’s data and to prevent unnecessary loss of income. In this study, a new m-coupon protocol is proposedand analyzed against well-known attacks: impersonation, man-in-the-middle, eavesdropping, replay, data modification,unauthorized coupon copying/generation, and multiple cash-in attacks. Then, to show that both the client and theretailer’s data are at the highest level of security, the protocol is subjected to security analysis with a powerful protocolanalysis tool, Scyther. Thus, the proposed protocol is proved to meet all safety criteria. To the best of our knowledge,this protocol is the first m-coupon protocol for which formal security analysis is conducted by the protocol’s developers.